EverShelf: why it is not safe to use
EverShelf passed most checks, but optional integrations can send household and health-related data plus credentials to external services you configure.
What we found
Our review did not find hidden instructions, hardcoded secrets, obfuscated code, undisclosed remote execution, or privilege escalation in the inspected repo. The warning came from EverShelf's optional integrations.
If enabled by the user, EverShelf can send pantry, shopping, recipe, backup, webhook, text-to-speech, and health-derived data to external services named in the project, including OpenAI, Gemini, Bring!, Home Assistant endpoints, Google Drive, custom HTTP TTS URLs, and a user server through an Android Health Connect bridge. The repo also supports connected-account credentials such as Bring! login details, Home Assistant tokens, Google Drive backup credentials, and API tokens needed for those services.
What to do instead
Use EverShelf only with the integrations you actually need, and review each destination before enabling it. Prefer local-only operation where possible. Limit tokens to the smallest scope available, store them outside the repo, and avoid sending health-related or household data to third-party endpoints unless that transfer is necessary for your setup. If backups, webhooks, or TTS are enabled, point them only to services you trust and control.
Source: https://github.com/dadaloop82/EverShelf
We report what our security review found at the time we checked, with the goal of keeping people safe. Projects change; if a maintainer has since fixed this, we are glad to recheck it. Email hello@agentpod.com.